Legal

SweQR Privacy Policy

How SweQR processes personal data

Effective date: 29 August 2026 · Last updated: 29 August 2026

1. About this Policy

This Privacy Policy explains how SweQR processes personal data when you visit sweqr.com, use the public Design Studio, create or use an account, create or manage a Dynamic QR identity, scan a SweQR-managed Dynamic QR, contact us, submit an abuse report, or otherwise interact with the Service.

The data controller is Thomas Johansson, a sole trader established in Sweden and trading as SweQR, with public business address Mejramvägen 16, 611 45 Nyköping, Sweden (“SweQR”, “we”, “us” or “our”). Privacy contact: hello@sweqr.com.

This Policy does not govern a third-party destination reached through a QR code. The destination operator is responsible for its own processing. Paddle independently processes buyer and payment information as Merchant of Record under Paddle’s own privacy notice.

2. Personal data we process

2.1. Account and profile data

We process information such as your email address, account identifier, authentication and verification status, selected language, plan and entitlement information, consent records, account roles, security settings and account creation or update timestamps. If you use third-party sign-in, we receive the identifiers and profile information that provider makes available for authentication.

2.2. Static designs and managed Dynamic QR data

The public Design Studio generates a true Static QR payload and artwork in the user’s browser. The final URL or other content is encoded directly in the artwork. Creating a true Static QR does not create a managed QR record, short code, redirect mapping or account-owned QR identity. Ordinary web-security and request logs may still be created when the person visits the Design Studio, but SweQR does not receive a later scan merely because the artwork was created there.

For managed Dynamic QR codes, SweQR processes the permanent short code and assigned redirect hostname, current destination, QR name or note, design assets, creation and update records, account ownership, Custom Domain information, validation results, safety and lifecycle status, and applicable entitlement and capacity information. A destination URL or uploaded asset may contain personal data if you place it there. Do not submit sensitive personal data unless it is lawful and necessary.

2.3. Static scans and managed Dynamic redirects

When somebody scans a true Static QR, the scanner’s device reads the final encoded URL or other content directly. No request is made to SweQR merely because SweQR’s Design Studio generated the artwork. SweQR therefore receives no redirect request, creates no SweQR scan telemetry and provides no Dynamic analytics for that scan. The encoded destination, the scanner’s network provider and the scanner’s device may process data under their own rules.

When somebody requests a SweQR-managed Dynamic link, SweQR and its edge provider process the requested hostname and short code, date and time, response and safety outcome, and limited browser, device, referrer-host, country and diagnostic information where available. Durable analytics are daily request aggregates and are approximate; they are not verified counts of unique people. This data is used to deliver the redirect, protect scanners and infrastructure, diagnose incidents and provide plan-eligible analytics.

Network infrastructure necessarily processes the scanner’s IP address to route and secure the request. The SweQR application does not intentionally write the raw scanner IP address to its Postgres scan-analytics tables or structured resolver-event payloads. Abuse controls derive a keyed, day-rotated pseudonymous source value. Reusable source-control tables are configured for 48-hour retention, but the reporter hash stored with a public abuse report remains with that report for its 180-day retention window. Pseudonymisation does not by itself make the value anonymous.

Those provider logs are retained under the enabled service configuration and applicable provider agreement. SweQR limits access and keeps such data only for service delivery, security, incident investigation and legal obligations, with periodic review of whether continued retention is necessary.

SweQR does not require a scanner to create an account merely to follow an ordinary Dynamic redirect.

2.4. Billing and transaction data

Paddle acts as authorised reseller and Merchant of Record for paid transactions and independently collects buyer identity, payment method, billing address, tax and transaction information. SweQR receives limited buyer, order, subscription, entitlement, refund, dispute and fraud-related information needed to deliver the Service, manage account access, reconcile payments and provide product support. SweQR does not receive or store full payment-card numbers.

2.5. Support, abuse and communications data

We process messages, attachments, contact details, support history, abuse notices, evidence, affected URLs or QR identities, enforcement decisions, statements of reasons and related communications. Please avoid sending unnecessary sensitive information.

2.6. Security and administration data

Authenticated security and provider-generated records are retained only for as long as needed to secure accounts, investigate incidents, meet legal obligations and defend claims. The period depends on the record and provider configuration; access is restricted and continued necessity is reviewed.

2.7. Website, cookies and marketing data

The Service uses essential browser storage and similar technologies for authentication, security, session continuity, preferences and core operation. Account sessions are stored in browser local storage under the current authentication implementation. Cloudflare or another infrastructure provider may use strictly necessary security or challenge technologies when protecting a request.

SweQR offers optional Google Analytics 4 measurement for the public website. If you allow it, Google may process information about public pages viewed, device and browser characteristics, approximate location, referral information and interaction time to provide aggregated website measurement. The application sends public page paths without query parameters and does not intentionally send account email addresses, QR destinations, QR names, payment information or other Customer Content to Google Analytics.

Google Analytics remains off unless you actively allow analytics through the Cookie settings control. We store that choice in essential browser local storage so we can remember it. You can withdraw or change your choice at any time through the same control. SweQR does not enable Google advertising storage, ad-user-data or ad-personalisation features through this implementation. Blocking essential storage may prevent parts of the Service from functioning.

If SweQR offers optional marketing communications, we process the email address, consent record and necessary delivery information and provide an unsubscribe route. Account verification, password recovery, service, security, billing and legal communications are not marketing.

3. Where the data comes from

  • directly from you when you register, configure the Service, upload content, buy a plan, contact support or submit a report;
  • automatically from browsers, devices, redirects, security systems and service logs;
  • from Paddle and other providers involved in authentication, payment, delivery, security and communications;
  • from public or specialist sources used to assess destination safety, such as domain-registration, reputation, threat and abuse information; and
  • from third parties who submit an abuse notice, legal request or security report.

4.1. Contract

We process information necessary to provide a requested Design Studio session and, for account holders, to create and administer the account, issue and operate managed Dynamic identities, maintain destinations, provide Custom Domain and team functions, authenticate users, provide support and apply plan entitlements. A later scan of a true Static QR is not processed by SweQR under the customer’s account contract.

4.2. Legitimate interests

We process limited data where necessary for our legitimate interests in securing accounts and infrastructure; detecting phishing, fraud and abuse; protecting scanners and redirect-domain reputation; maintaining the permanent non-reuse ledger for issued identities; diagnosing failures; defending legal claims; improving reliability; and understanding aggregated use of the Service. We assess these interests against affected individuals’ rights and use data minimisation, access controls, short log-retention periods and human review where appropriate.

The permanent issuance ledger is retained under legitimate interest specifically for its role after an individual customer relationship ends or a code is deactivated. Ensuring that a short code and redirect hostname are never reassigned protects every SweQR customer and scanner, not only the account that originally created the code. While an account is active, the same data is also processed under section 4.1 (Contract) to operate the issued codes.

5. Redirect safety and automated processing

Google may process lookup data under the applicable Google Cloud service terms and privacy documentation; SweQR limits the submitted data to what is necessary for the destination-safety check.

An unverified report or heuristic signal is suspicion rather than a confirmed malicious verdict and ordinarily results in review, an interstitial or another reversible measure. A confirmed malicious verdict from an approved trusted provider may produce an immediate automated block. The check concerns destination safety rather than personal characteristics of an individual. An automated confirmed block is not automatically reversed; reversal requires an authorised human decision.

A true Static QR does not pass through SweQR when later scanned, so SweQR cannot continuously inspect or block its encoded destination after download.

A person affected by an automated safety restriction may request human review through hello@sweqr.com. Decision reasons are recorded internally, and a legally required customer-facing notice may be sent manually by email.

6. How we share personal data

We use the following service providers and independent recipients where necessary for the stated purposes. Their role depends on the service and transaction:

  • Lovable and Lovable Cloud: application platform, hosting and managed functions. Supabase provides database and authentication components within the Lovable-managed architecture; SweQR does not claim a direct Supabase contract without account evidence.
  • Cloudflare: SweQR’s direct Workers Paid account, edge handling, Workers, KV projection, security and delivery of managed Dynamic redirects. Cloudflare necessarily processes scanner network addresses at the edge.
  • Resend: normal SweQR transactional email from no-reply@sweqr.com. Signup verification and password recovery from noreply@notify.sweqr.com use Lovable-managed authentication email rather than a separately claimed SweQR transport contract.
  • Google Cloud Web Risk: complete managed Dynamic destination URLs for threat lookup. Google Identity: optional Google sign-in when selected by the user. Google Analytics 4: optional public-website measurement only after a visitor actively allows analytics through Cookie settings.
  • Paddle: authorised reseller, Merchant of Record and independent party for buyer relationship, checkout, payment, tax, recurring-charge, transaction refund, receipt, fraud and buyer-payment-support processing. SweQR receives limited transaction data for fulfillment, entitlement, reconciliation and product support.
  • Namecheap: domain registration and SweQR business mailbox services. UptimeRobot: public service-availability monitoring configured to avoid customer QR identities in canaries. GitHub: private source code, development review and CI; no production customer records or Customer Content are intentionally stored there.

We may also disclose limited data to professional advisers, auditors, insurers and transaction parties under confidentiality protections; to authorities, courts or regulators where lawfully required; or to a successor in a lawful reorganisation or transfer.

We do not sell personal data. SweQR does not intentionally use Customer Content to train its own machine-learning models or license Customer Content to third parties for their own purposes. Service providers may process data only for the contracted service and under their applicable terms and data-protection obligations. You may contact hello@sweqr.com for current information about the providers and recipients relevant to your use of the Service.

7. International data transfers

SweQR is established in Sweden. Some providers may process personal data outside Sweden or the European Economic Area. A restricted international transfer is made only where a lawful mechanism is available, such as an applicable adequacy decision, the European Commission’s Standard Contractual Clauses with supplementary safeguards where required, or another mechanism permitted by data-protection law. You may contact hello@sweqr.com for information about safeguards relevant to a particular transfer.

8. How long we retain data

We retain personal data only for as long as necessary for the stated purpose, subject to legal holds, security investigations, active disputes, accounting obligations and applicable infrastructure backup cycles. The following periods are supported by current application configuration and purge-job evidence:

  • Static QR scans: no SweQR redirect record or scan telemetry is created merely because a true Static QR made in the Design Studio is scanned.
  • Reusable pseudonymous source-control tables: 48 hours. The pseudonymous reporter hash held with a public abuse report follows the report’s 180-day period rather than the 48-hour source-table period.
  • Guardrail/rate-control event records: 3 days. Product-event records, which may be linked to an account and may contain limited event properties, and terminal transactional-email outbox records: 90 days. Product-event properties must remain minimised to the documented event purpose.
  • Safety-chain observations, where generated: 90 days. The chain-observation feature is disabled in the current runtime; the period applies to any records that exist.
  • Abuse signals: 90 days. Public abuse-report records, including optional details and reporter hash: 180 days. Resolved abuse-review records: 365 days after resolution. Unresolved matters remain until resolved; a legal hold or active proceeding may require longer.
  • Aggregated managed Dynamic scan statistics and facets: up to 1,130 days. These tables contain daily counts and limited facets and do not contain raw scanner IP.
  • Permanent issued-identity ledger: the issued short code, redirect hostname, issuance/account reference and non-reuse status are retained permanently so no issued identity can be assigned to somebody else.
  • Deactivated issued-code mapping after completed account deletion: the former destination is replaced with a neutral non-resolving value, and destination and host values in the destination-change history are redacted at completion. The history rows remain with actor, reason and timestamps so authorised actions remain auditable. The permanent code, redirect hostname and pseudonymous internal account reference remain for referential integrity and identity-reservation proof.
  • Account/authentication data: retained while required for an active account. On completed deletion the account closes and memberships are removed. The workflow attempts to delete an authentication identity only when it is not required by another active SweQR account, remove saved account designs and short-lived request-source records, and clear customer-authored QR notes. The completion result and any failed cleanup must be reviewed rather than treating the request alone as proof of erasure.
  • Support, administrative audit, security, safety, destination-history and SweQR billing records: retained for the period reasonably necessary to resolve the matter, protect the Service, demonstrate authorised actions, meet legal obligations or establish, exercise or defend claims. Active investigations, disputes and legal holds may require longer retention.
  • Transaction and accounting records: retained for the period required by applicable accounting and tax law. Paddle retains its own transaction records under its privacy notice. Essential browser storage follows the session or purpose for which it is set. Backups are overwritten or deleted under the applicable infrastructure backup cycle and may remain inaccessible to ordinary operations until that cycle completes.

A request for erasure does not require deletion of data that SweQR must or may lawfully retain, but retained data must be limited to and protected for the applicable purpose.

9. Account deletion and issued QR identities

Account deletion is a staged, human-reviewed process available to the account owner. The owner chooses whether all issued Dynamic QR codes should keep resolving or be deactivated. The current flow does not support a different choice for each code.

The deletion process does not automatically cancel an active Paddle subscription. Completion is blocked until the subscription has been cancelled through Billing or Paddle and the resulting billing state has been reconciled.

On completion, the account closes and memberships/invitations are removed or revoked. The workflow attempts to clear QR notes, remove saved designs and short-lived account request-source records, and delete an authentication identity only where it is not still needed for another active account. The completion record must be checked and failed cleanup followed up. If deactivation was selected, issued codes stop redirecting; otherwise they continue under their existing destination, safety and lifecycle state.

In both cases, issued-code rows retain the permanent short code, redirect hostname, a pseudonymous internal account reference and necessary safety/lifecycle state. If deactivation was selected, the former destination is replaced with a neutral non-resolving value and destination and host values in the destination-change history are redacted; if keep-active was selected, the last permitted destination remains because the code continues resolving. Custom Domain records carrying issued identities are retained. Support cases and billing, security, safety and audit history may remain.

These retained elements are access-restricted and remain subject to necessity review, legal obligations and the rights described below.

10. Your data-protection rights

Depending on applicable law, you may have the right to:

  • receive information about our processing and obtain access to your personal data;
  • correct inaccurate or incomplete data;
  • request erasure or restriction of processing;
  • object to processing based on legitimate interests, including direct marketing;
  • withdraw consent at any time;
  • receive data you provided in a structured, commonly used and machine-readable format where the right to portability applies; and
  • lodge a complaint with a data-protection authority.

To exercise a right, contact hello@sweqr.com. We may need to verify your identity and may ask for information needed to locate the relevant data. We normally respond within one month. Where a request is complex or we receive a high number of requests, this may be extended by up to two further months; if so, we will tell you within the first month and explain the reason for the delay. Rights are not absolute; if we cannot comply fully, we will explain the applicable reason where permitted.

If you are in Sweden, you may complain to Integritetsskyddsmyndigheten (IMY), www.imy.se. You may also contact the supervisory authority where you live, work or believe an infringement occurred.

11. Cookies and similar technologies

SweQR uses essential browser storage and similar technologies for authentication, security, session continuity, preferences and core operation. Infrastructure providers may also use strictly necessary security or challenge technologies when protecting a request. Blocking essential storage may prevent parts of the Service from functioning.

Google Analytics 4 is optional and does not load until you actively allow analytics through Cookie settings. The control records your allow or reject choice in essential browser local storage and remains available so you can change or withdraw it. SweQR does not enable Google advertising storage, ad-user-data or ad-personalisation features through this implementation.

12. Security

We use technical and organisational measures intended to protect personal data, including access controls, authentication protections, encryption in transit, audit logging, role separation, safety controls, backups and monitoring. No system is completely secure. Report a suspected security incident to security@sweqr.com. General privacy requests remain directed to hello@sweqr.com.

13. Children

SweQR accounts, paid plans and managed Dynamic QR functions are intended only for people who are at least 18 years old. A person under 18 should use the public Design Studio only with the involvement of a parent or legal guardian where required by applicable law.

14. Changes to this Policy

We may update this Policy to reflect changes in law, providers, features or processing. We will publish the updated version and revise the “Last updated” date. Where a change materially affects individuals, we will provide additional notice where required.

15. Contact

Data controller: Thomas Johansson, sole trader trading as SweQR

Public business address: Mejramvägen 16, 611 45 Nyköping, Sweden

Privacy email: hello@sweqr.com

Security reports: security@sweqr.com

SweQR has not appointed a formal Data Protection Officer. Privacy enquiries are handled through hello@sweqr.com.